Apple Pay Token Decryption Docs Contain Key Derivation Error, Dev Warns
A developer has flagged that Apple's live reference page for decrypting Apple Pay tokens contains an error in the key derivation function table, listing the hash function where the shared secret should appear and omitting critical AES-256-GCM algorithm ID bytes. The mistake means anyone building a decryptor from the current documentation will generate a key that fails to decrypt the ciphertext, with no informative error to indicate why. The correct values remain visible in an archived version of the same page. A detailed technical guide has been published covering the actual decryption flows for Apple Pay's EC_v1 and RSA_v1 formats and Google Pay's ECv2, including signature verification steps and certificate rotation practices that are commonly skipped. The guide also addresses a broader question of whether merchants should be handling token decryption themselves, rather than delegating it to a payment service provider.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in